ConditionalAccess icon indicating copy to clipboard operation
ConditionalAccess copied to clipboard

Logic to protect inclusion and exclusion groups

Open AlexFilipin opened this issue 4 years ago • 2 comments

We might want to protect exclusion groups (at least some) with the "Azure AD roles can be assigned to the group" flag that will protect it from other admin roles.

Thinking about: Sync account group, Emergency access account group and admin CA policies maybe even PERM exclusion groups of other policies.

AlexFilipin avatar Nov 16 '20 13:11 AlexFilipin

microsoft.directory/groups/members/update

  • Group Owner (via User Role)
  • User Account Administrator
  • Partner Tier1 Support
  • Partner Tier2 Support
  • Directory Writers
  • Groups Administrator

microsoft.directory/groups/allProperties/allTasks

  • Global Administrator

microsoft.directory/groups.unified/members/update

  • Exchange Service Administrator
  • SharePoint Service Administrator
  • Teams Service Administrator

microsoft.directory/groups.security/members/update

  • Intune Service Administrator

microsoft.directory/groups.assignableToRoles/allProperties/update

  • Global Administrator
  • Privileged Role Administrator
  • Group Owner (via User Role)

AlexFilipin avatar Nov 16 '20 13:11 AlexFilipin

Waiting for additional AAD features, the number of assignableToRoles groups is limited so I dont think its a good path to take.

AlexFilipin avatar Sep 03 '21 22:09 AlexFilipin